AI Voice “Apple Support” Phishing + Fake IT Helpdesk

About DFIR · High sophistication
Last updated August 27, 2026

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing emails posing as an organization’s IT help desk to deliver malware that shows a fake Windows lock screen to capture passwords.

Key findings

  • A phishing-as-a-service (PhaaS) platform (“AnonyMousKIT”) impersonates Apple support across email, SMS, WhatsApp, and AI voice calls to steal iPhone passcodes for unlocking/resale of stolen phones.
  • Researchers attributed the AnonyMousKIT operation to a large infrastructure footprint: “506 domains and 168 reseller storefronts.”
  • A separate malware family (“SynkLoader”) is delivered by “phishing emails that impersonate an organization’s IT help desk,” then uses a “fake Windows lock-screen module” to trick victims into typing their password.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, IT Help Desk, HR, Customer support / frontline staff.
  • Affected industries: Consumers / mobile device owners, Any organization with an IT help desk and email users.
  • Attack channels: email, smishing, whatsapp, vishing.
  • Impersonated: Apple Support, Organization IT Help Desk.

Awareness takeaways

  • Treat any request for a passcode (or MFA/credentials) as a scam, even if it sounds like “support.”
  • Train staff to expect multi-channel attacks (email + texts + WhatsApp + calls) and to stop and verify through official channels.
  • Remind employees that IT will not “lock” their screen via email-driven actions and ask them to type passwords into unexpected prompts, report it immediately.

Red flags to watch for

  • Any “support” request asking for a device passcode is illegitimate
  • Pressure/urgency to act so the device can be wiped/unlocked
  • Unexpected contact across multiple channels (email/SMS/WhatsApp/voice) about the same issue
  • Unexpected “IT help desk” email from an unfamiliar Microsoft 365 tenant
  • A sudden lock screen that asks you to type your password to “unlock” (especially outside normal login flow)
  • Email-driven “fix” that results in software running or prompts appearing
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: your iPhone goes missing, and minutes later “Apple Support” is calling, texting, and WhatsApping you at the same time. That’s AnonyMousKIT, a phishing-as-a-service platform that impersonates Apple Support by email, SMS, WhatsApp, and AI voice calls, convincing people to read out their iPhone passcode so stolen phones can be wiped, unlocked, and resold. There’s a cousin to this: SynkLoader arrives as a fake IT help desk email from a lookalike Microsoft 365 tenant, then pops up a fake Windows lock screen that says “enter your password to unlock” and quietly steals it. Here’s the rule: if anyone, Apple, IT, anyone, asks for a passcode or password, stop and report it to our security team immediately through our normal reporting channel.

Similar attacks

Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026